9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentially sensitive objects to be reached from within a template. If an application developer passes unvalidated user input directly to the template engine, an unauthenticated remote attacker can bypass the library's protections to achieve Server-Side Template Injection (SSTI). This issue has ben fixed in version 3.1.4.RELEASE.
AI Analysis
Server-Side Template Injection (SSTI) vulnerability due to improper restriction of accessible objects in Thymeleaf expressions
Basic Information
ID
CVE-2026-40477
Source
GitHub_M
Published
Apr 17, 2026 at 21:53
Affected Product
Vendor
thymeleaf
Product
thymeleaf
Version
< 3.1.4.RELEASE
Affected Versions
thymeleaf thymeleaf < 3.1.4.RELEASE
thymeleaf org.thymeleaf:thymeleaf-spring5 < 3.1.4.RELEASE
thymeleaf org.thymeleaf:thymeleaf-spring6 < 3.1.4.RELEASE
thymeleaf org.thymeleaf:thymeleaf-spring5 < 3.1.4.RELEASE
thymeleaf org.thymeleaf:thymeleaf-spring6 < 3.1.4.RELEASE
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
Thymeleaf
Product
Thymeleaf
Version
3.1.3.RELEASE and prior